{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:24:34Z","timestamp":1750307074029,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":43,"publisher":"ACM","license":[{"start":{"date-parts":[[2012,12,3]],"date-time":"2012-12-03T00:00:00Z","timestamp":1354492800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100004963","name":"Seventh Framework Programme","doi-asserted-by":"publisher","award":["STREWS (FP7-318097)WebSand (FP7-256964)"],"award-info":[{"award-number":["STREWS (FP7-318097)WebSand (FP7-256964)"]}],"id":[{"id":"10.13039\/501100004963","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2012,12,3]]},"DOI":"10.1145\/2420950.2420977","type":"proceedings-article","created":{"date-parts":[[2012,12,19]],"date-time":"2012-12-19T14:12:22Z","timestamp":1355926342000},"page":"169-178","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["BetterAuth"],"prefix":"10.1145","author":[{"given":"Martin","family":"Johns","sequence":"first","affiliation":[{"name":"SAP Research"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sebastian","family":"Lekies","sequence":"additional","affiliation":[{"name":"SAP Research"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bastian","family":"Braun","sequence":"additional","affiliation":[{"name":"University of Passau"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Benjamin","family":"Flesch","sequence":"additional","affiliation":[{"name":"SAP Research"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2012,12,3]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/1367497.1367568"},{"volume-title":"Version","year":"2011","author":"Balfanz D.","key":"e_1_3_2_1_2_1"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455782"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.5555\/882488.884178"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/168588.168618"},{"key":"e_1_3_2_1_6_1","first-page":"2011","author":"Bortz A.","year":"2011","journal-title":"Origin Cookies: Session Integrity for Web Applications. In W2SP"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046734"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1073001.1073009"},{"key":"e_1_3_2_1_9_1","unstructured":"P. Eckersley. How secure is HTTPS today? How often is it attacked? {online} https:\/\/www.eff.org\/deeplinks\/2011\/10\/how-secure-https-today October 2011.  P. Eckersley. How secure is HTTPS today? How often is it attacked? {online} https:\/\/www.eff.org\/deeplinks\/2011\/10\/how-secure-https-today October 2011."},{"key":"e_1_3_2_1_10_1","unstructured":"P. Eckersley and J. Burns. The (Decentralized) SSL Observatory. Invited Talk Usenix Security 2011 http:\/\/static.usenix.org\/events\/sec11\/tech\/slides\/eckersley.pdf August 2011.  P. Eckersley and J. Burns. The (Decentralized) SSL Observatory. Invited Talk Usenix Security 2011 http:\/\/static.usenix.org\/events\/sec11\/tech\/slides\/eckersley.pdf August 2011."},{"key":"e_1_3_2_1_11_1","unstructured":"I. H. (Ed. Web Storage. W3C Candidate Recommendation http:\/\/www.w3.org\/TR\/webstorage\/ December 2011.  I. H. (Ed. Web Storage. W3C Candidate Recommendation http:\/\/www.w3.org\/TR\/webstorage\/ December 2011."},{"volume-title":"Proceedings of W2SP","year":"2009","author":"Engler J.","key":"e_1_3_2_1_12_1"},{"volume-title":"Version","year":"2012","author":"Fielding R.","key":"e_1_3_2_1_13_1"},{"key":"e_1_3_2_1_14_1","unstructured":"Google. Safe Browsing for Firefox. {application} http:\/\/www.google.com\/tools\/firefox\/safebrowsing\/ (03\/20\/06) 2006.  Google. Safe Browsing for Firefox. {application} http:\/\/www.google.com\/tools\/firefox\/safebrowsing\/ (03\/20\/06) 2006."},{"key":"e_1_3_2_1_15_1","unstructured":"R. Hansen and J. Grossman. Clickjacking. {online} http:\/\/www.sectheory.com\/clickjacking.htm last accessed 02\/13\/12 August 2008.  R. Hansen and J. Grossman. Clickjacking. {online} http:\/\/www.sectheory.com\/clickjacking.htm last accessed 02\/13\/12 August 2008."},{"key":"e_1_3_2_1_16_1","unstructured":"E. Henning. Trustwave issued a man-in-the-middle certificate. {online} http:\/\/www.h-online.com\/security\/news\/item\/Trustwave-issued-a-man-in-the-middle-certificate- 1429982.html February 2012.  E. Henning. Trustwave issued a man-in-the-middle certificate. {online} http:\/\/www.h-online.com\/security\/news\/item\/Trustwave-issued-a-man-in-the-middle-certificate- 1429982.html February 2012."},{"volume-title":"Version","year":"2012","author":"Hodges J.","key":"e_1_3_2_1_17_1"},{"volume-title":"IEEE International Workshops on, 0:  0248","year":"1997","author":"Jablon D.","key":"e_1_3_2_1_18_1"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1367497.1367569"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/11863908_27"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/1982185.1982511"},{"key":"e_1_3_2_1_22_1","unstructured":"D. Kaminsky. h0h0h0h0. Talk at the ToorCon Seattle Conference http:\/\/seattle.toorcon.org\/2008\/conference.php?id=42 April 2008.  D. Kaminsky. h0h0h0h0. Talk at the ToorCon Seattle Conference http:\/\/seattle.toorcon.org\/2008\/conference.php?id=42 April 2008."},{"key":"e_1_3_2_1_23_1","unstructured":"A. Klein. \"Divide and Conquer\" - HTTP Response Splitting Web Cache Poisoning Attacks and Related Topics. Whitepaper Sanctum Inc. http:\/\/packetstormsecurity.org\/papers\/general\/whitepaper_httpresponse.pdf March 2004.  A. Klein. \"Divide and Conquer\" - HTTP Response Splitting Web Cache Poisoning Attacks and Related Topics. Whitepaper Sanctum Inc. http:\/\/packetstormsecurity.org\/papers\/general\/whitepaper_httpresponse.pdf March 2004."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"crossref","unstructured":"H. Krawczyk M. Bellare and R. Canetti. HMAC: Keyed-Hashing for Message Authentication. RFC 2104 http:\/\/tools.ietf.org\/html\/rfc2104 February 1997.   H. Krawczyk M. Bellare and R. Canetti. HMAC: Keyed-Hashing for Message Authentication. RFC 2104 http:\/\/tools.ietf.org\/html\/rfc2104 February 1997.","DOI":"10.17487\/rfc2104"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.33"},{"key":"e_1_3_2_1_26_1","unstructured":"M. Marlinspike. New Tricks For Defeating SSL In Practice. Talk at the Black Hat DC conference 2009.  M. Marlinspike. New Tricks For Defeating SSL In Practice. Talk at the Black Hat DC conference 2009."},{"key":"e_1_3_2_1_27_1","unstructured":"Microsoft. Ie8 security part vii: Clickjacking defenses 2009.  Microsoft. Ie8 security part vii: Clickjacking defenses 2009."},{"key":"e_1_3_2_1_28_1","unstructured":"MSDN. Mitigating Cross-site Scripting With HTTP-only Cookies. {online} http:\/\/msdn.microsoft.com\/workshop\/author\/dhtml\/httponly_cookies.asp (01\/23\/06).  MSDN. Mitigating Cross-site Scripting With HTTP-only Cookies. {online} http:\/\/msdn.microsoft.com\/workshop\/author\/dhtml\/httponly_cookies.asp (01\/23\/06)."},{"volume-title":"Document Structure Integrity: A Robust Basis for Cross-site Scripting Defense. In Network & Distributed System Security Symposium (NDSS 2009)","year":"2009","author":"Nadji Y.","key":"e_1_3_2_1_29_1"},{"volume-title":"Proceedings of the W3C Security and Usability Workshop","year":"2006","author":"Nelson J.","key":"e_1_3_2_1_30_1"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.5555\/1946341.1946351"},{"volume-title":"Version","year":"2011","author":"Oiwa Y.","key":"e_1_3_2_1_32_1"},{"key":"e_1_3_2_1_33_1","unstructured":"Open Web Application Security Project. Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet. {online} https:\/\/www.owasp.org\/index.php\/Cross-Site_Request_Forgery_(CSRF)_Prevention_Cheat_Sheet accessed November 2011 2010.  Open Web Application Security Project. Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet. {online} https:\/\/www.owasp.org\/index.php\/Cross-Site_Request_Forgery_(CSRF)_Prevention_Cheat_Sheet accessed November 2011 2010."},{"key":"e_1_3_2_1_34_1","unstructured":"J. Ruderman. The Same Origin Policy. {online} http:\/\/www.mozilla.org\/projects\/security\/components\/same-origin.html (01\/10\/06) August 2001.  J. Ruderman. The Same Origin Policy. {online} http:\/\/www.mozilla.org\/projects\/security\/components\/same-origin.html (01\/10\/06) August 2001."},{"volume-title":"Web 2.0 Security and Privacy (W2SP","year":"2010","author":"Rydstedt G.","key":"e_1_3_2_1_35_1"},{"volume-title":"IEEE","year":"2008","author":"Sandler D.","key":"e_1_3_2_1_36_1"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"crossref","unstructured":"M.\n       \n      Sharifi A.\n       \n      Saberi M.\n       \n      Vahidi and \n      \n      \n      M.\n       \n      Zoroufi\n      \n  \n  . \n  A Zero Knowledge Password Proof Mutual Authentication Technique Against Real-Time Phishing Attacks. In P. D. McDaniel and S. K. Gupta editors ICISS volume \n  4812\n   of \n  Lecture Notes in Computer Science pages \n  254\n  --\n  258\n  . \n  Springer 2007\n  .   M. Sharifi A. Saberi M. Vahidi and M. Zoroufi. A Zero Knowledge Password Proof Mutual Authentication Technique Against Real-Time Phishing Attacks. In P. D. McDaniel and S. K. Gupta editors ICISS volume 4812 of Lecture Notes in Computer Science pages 254--258. Springer 2007.","DOI":"10.1007\/978-3-540-77086-2_20"},{"key":"e_1_3_2_1_38_1","unstructured":"E. Shepherd. window.postmessage. {online} https:\/\/developer.mozilla.org\/en\/DOM\/window.postMessage last accessed 02\/12\/12 October 2011.  E. Shepherd. window.postmessage. {online} https:\/\/developer.mozilla.org\/en\/DOM\/window.postMessage last accessed 02\/12\/12 October 2011."},{"volume-title":"Drive-by Pharming. In In Proceedings of Information and Communications Security (ICICS '07)","year":"2007","author":"Stamm S.","key":"e_1_3_2_1_39_1"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/501963.501965"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/1143120.1143133"},{"key":"e_1_3_2_1_42_1","first-page":"97","volume-title":"Proceedings of the 1998 Internet Society Network and Distributed System Security Symposium","author":"Wu T.","year":"1998"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.5555\/646280.687663"}],"event":{"name":"ACSAC '12: Annual Computer Security Applications Conference","sponsor":["ACSA Applied Computing Security Assoc"],"location":"Orlando Florida USA","acronym":"ACSAC '12"},"container-title":["Proceedings of the 28th Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2420950.2420977","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2420950.2420977","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T09:33:57Z","timestamp":1750239237000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2420950.2420977"}},"subtitle":["web authentication revisited"],"short-title":[],"issued":{"date-parts":[[2012,12,3]]},"references-count":43,"alternative-id":["10.1145\/2420950.2420977","10.1145\/2420950"],"URL":"https:\/\/doi.org\/10.1145\/2420950.2420977","relation":{},"subject":[],"published":{"date-parts":[[2012,12,3]]},"assertion":[{"value":"2012-12-03","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}